### [CVE-2021-27956](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-27956) ![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brighgreen) ### Description Zoho ManageEngine ADSelfService Plus before 6104 allows stored XSS on the /webclient/index.html#/directory-search user search page via the e-mail address field. ### POC #### Reference - https://raxis.com/blog/cve-2021-27956-manage-engine-xss - https://www.manageengine.com #### Github - https://github.com/ARPSyndicate/cvemon - https://github.com/k0pak4/k0pak4